Vendor due diligence in Chile: what the law requires and how to tier the review by risk

Reviewing vendors means deciding which ones, how deep, and what clauses each contract carries. Three Chilean laws answer those questions from different angles, and a single review, tiered by risk, serves all three.

Last updated:

In Chile, vendor review has no regulation under that name, but three regimes make the company answer for its third parties: Law 20.393, for the crimes of those who manage its affairs before others; Law 19.628, for the mandatario or encargado (the data processor) that handles its data, and Law 21.663, which requires regulated institutions to prevent and manage their cybersecurity risks, and in practice those risks include the ones their vendors bring. The review is tiered by the risk of each relationship: the same vendor may sit at two levels under two different contracts.

Why the vendor is the company's own risk: Law 20.393 after Law 21.595

The attribution rule reaches beyond employees, and the prevention model has to reach just as far.

That rule is in Article 3 of Law 20.393, which makes the company criminally liable for a listed crime perpetrated within its activity by or with the intervention of a natural person who holds a position, function or post in it, or who provides it services managing its affairs before third parties, with or without its representation. Liability also requires that the lack of effective implementation of an adequate prevention model favored or facilitated the act. The second paragraph extends the rule to an act perpetrated through a natural person linked to a different legal entity, when that entity provides it services managing its affairs before third parties or lacks operational autonomy with respect to it, "cuando entre ellas existan relaciones de propiedad o participación" (where there are ownership or participation relations between them). The law does not clarify whether this last requirement applies to both hypotheses or only to the lack of autonomy. The third paragraph excludes an act perpetrated exclusively against the legal entity itself, such as a vendor's fraud that harms only the company.

Article 4 then describes when the model is adequate to exempt the company from criminal liability, to the extent required by its corporate purpose, line of business, size, complexity, resources and activities: the identification of the activities or processes that carry criminal risk (No. 1); protocols to prevent and detect those conducts, which must necessarily consider secure reporting channels and internal sanctions (No. 2); one or more persons in charge with independence, powers and resources, the encargado de prevención de delitos (the crime prevention officer) (No. 3), and periodic evaluations by independent third parties (No. 4). No. 2 adds the sentence that takes the model into the contract with the vendor: the internal rules must be expressly incorporated into the employment and service contracts of all workers, employees and service providers, including top executives. It is a condition for the model to serve as an exemption, and it reaches every service provider. The law does not require reviewing the vendor; the review is the way to identify which of those contracts concentrate the risk of No. 1.

The practical consequence is to distinguish vendors by what they do for the company. A supplier of goods with no access to authorities, clients or company systems generates little attributable risk. An agent, a permit manager or a debt collector who acts before third parties on the company's behalf is the person described in the first paragraph of Article 3; a group entity that does the same or lacks operational autonomy, the one in the second paragraph. If the vendor is an external company with no ownership link, such as a customs agency or a collection company, the scope of Article 3 is debatable: it depends on whether the natural person acting for that company provides services to yours in the terms of the first paragraph and on how the ownership or participation requirement of the second paragraph is read. A distributor that buys and resells on its own account normally does not manage the company's affairs, unless it does so before authorities or clients, with or without its representation. In case of doubt, the risk justifies treating them at the highest level. The prevention model is explained in the crime prevention model and the liability regime in Law 20.393.

Personal data: the written mandate today and the processor from Law 21.719

Today the written mandate of Article 8 of Law 19.628 governs; with Law 21.719, the law itself will set the minimum content of the contract with the vendor.

That change has a date: Law 21.719 incorporates into Law 19.628 the rules that follow from December 1, 2026. A Government bill before the Senate (Bulletin 18.623-07) proposes to postpone that date to December 1, 2027. Until then, Article 8 of Law 19.628 governs: processing under a mandate is subject to the general rules, the mandate must be granted in writing, with express record of the conditions for using the data, and the mandatario must respect them. A contract signed today that remains in force in 2026 or 2027 is best drafted now with the content of the new Article 15 bis.

Under Article 15 bis, the controller (responsable) may process data directly or through a third-party mandatario or encargado, which processes only according to the assignment and the controller's instructions and may not use the data for a different purpose or transfer them without express and specific authorization. If the processor does either, it will be considered a controller for all legal purposes: it will answer personally for infringements and jointly and severally with the controller for damages. The contract will have to set out the object of the assignment, its duration, the purpose of the processing, the type of personal data, the categories of data subjects and the rights and obligations of the parties. Subcontracting will require specific written authorization, and a processor that delegates will remain jointly and severally liable. The processor will be subject to the duties of secrecy (Article 14 bis) and security (Article 14 quinquies), will have to inform the controller of security breaches and, once the service ends, delete or return the data.

Two rules of the reform matter for procurement. Article 1 bis will apply the law to a mandatario that processes data on behalf of a controller established in Chile, wherever it is incorporated; so a foreign cloud or payroll vendor will fall within the regime. And Article 14 septies will allow the Agencia de Protección de Datos Personales (the data protection agency) to set, by general instruction, differentiated security standards by type of data, company size and activity, applicable to the processor as well. For vendors that take data abroad, the transfer rules are in international data transfers and the general regime in the Data Protection Law.

Cybersecurity: duties of the regulated institution and of the technology vendor

Law 21.663 reaches most vendors through the duties it imposes on the regulated institution; it reaches the provider of managed technology services directly.

In Law 21.663, Article 7 requires the bound institutions to apply on a permanent basis technological, organizational, physical or informational measures "para prevenir, reportar y resolver incidentes de ciberseguridad" (to prevent, report and resolve cybersecurity incidents), implementing the protocols and standards of the Agencia Nacional de Ciberseguridad (the national cybersecurity agency) and the standards of their sectoral regulation. Article 9 requires all the institutions of Article 4 to report to the National CSIRT the incidents that may have significant effects: early warning within three hours, update within 72 hours (24 hours for an operator of vital importance whose essential services are affected) and final report within 15 calendar days. Article 8 adds, for operators of vital importance (operadores de importancia vital), a continuous information security management system that determines the risks for networks, systems, data and operational continuity, certified continuity plans reviewed at least every two years, exercises and drills, training programs for workers and collaborators, and a cybersecurity delegate. The same Article 8 governs the infrastructures, processes or functions the Agency identifies as essential (Article 4, final paragraph). Articles 7 and 8 do not name the vendor. The only explicit mention is in Article 9 and applies to State bodies: their heads of service must require information technology vendors to share information on vulnerabilities and incidents, and contracts may not restrict that communication.

For a bound private institution, the conclusion is the same as under the other two laws. Neither the permanent measures of Article 7 nor, where applicable, the management system of Article 8 letter a) can cover the risks of its networks without covering the vendors that operate or access them. The three-hour deadline of Article 9 is not met either if the vendor operating the systems does not give timely notice. The contract is the instrument that turns that analysis into obligations. Article 4 adds a point to check at the outset: digital services and managed information technology services provided by private institutions are, by law, essential services. The law does not define those two categories, so their exact scope will depend on how the Agency interprets them. But a vendor that fits them is a bound institution in its own right. Articles 7 and 9 apply to it, with measures the Agency must differentiate by type of organization, with special consideration for small and medium-sized enterprises (Article 7, fourth paragraph). Article 8 as well, if the Agency classifies it as an operator of vital importance or identifies its infrastructures, processes or functions as essential (Article 4, final paragraph). To find out whether your company is subject to the law, see the Cybersecurity Framework Law.

How to tier the review: three risk levels

One method serves all three laws: the vendor's activity sets the level, and the level sets what is verified, what evidence is kept and what clauses the contract carries.

LevelWhen it appliesWhat is reviewedEvidence keptContract clauses
BasicStandard goods or services, no contact with authorities or clients on the company's behalf, no access to personal data or systemsIdentity and tax status, legal representatives, sanctions lists, relevant open litigationVerification form with date and source of each checkInternal rules of the prevention model incorporated into the contract (Article 4 No. 2), right to terminate for breach
EnhancedProcesses personal data on the company's behalf, connects to its systems or operates in a sector with licenses or subsidiesThe basic checks plus ownership structure and beneficial owners, security measures, subcontractors, current licensesCompleted and signed questionnaire, security accreditations, list of authorized subcontractorsThe basic clauses plus audit rights; if it processes data on the company's behalf, a written mandate (Article 8 of Law 19.628) with the content of the future Article 15 bis, breach notice, prohibition on subcontracting without written authorization and return or deletion at the end; if it operates or accesses systems of an institution subject to Law 21.663, immediate incident notice
CriticalManages the company's affairs before third parties: agents, permit managers, debt collectors and related entities without operational autonomy; in case of doubt, also customs agencies, collection companies and distributors that manage the company's affairs before authorities or clientsThe enhanced checks plus politically exposed persons, reputation and prior sanctions, how and by whom it is paid, its own prevention modelWritten risk assessment approved by the prevention officer, periodic review, interview notesThe clauses of the previous levels as applicable, plus anti-corruption representations, audit and inspection rights, immediate termination and cooperation in investigations

The level is assigned to each relationship: the same company may sit at two levels under two different contracts. The document that matters is the one recording why a vendor ended up where it did. Article 4 asks the model to seriously and reasonably consider the aspects it lists, the first of them the identification of the processes with risk, and a reasoned tiering is evidence that that consideration took place. The review is repeated on a change in the relationship, a change in the vendor's ownership, an incident or the periodic evaluation of the model.

What goes into the contract

The review is worth what the obligations it produces are worth. These are the clauses worth agreeing to address the three laws: the first and the data clauses have an express legal source, and the rest are the means to enforce them.

  • Incorporation of its internal rules: the protocols and internal sanctions of the prevention model become part of the service contract, as Article 4 No. 2 of Law 20.393 requires for the model to be adequate. It applies to every service provider.
  • Reporting channel and cooperation: the vendor knows the secure reporting channel of Article 4 No. 2 and undertakes to cooperate in internal investigations.
  • Data processing clauses: today, the written mandate with the conditions for using the data required by Article 8 of Law 19.628; from the entry into force of Law 21.719, the content of Article 15 bis: object, duration, purpose, types of data, categories of data subjects, rights and obligations; subcontracting only with specific written authorization; notice of breaches to the controller; deletion or return at the end.
  • Incident notice: a vendor that operates or accesses networks and systems of an institution subject to Law 21.663 undertakes to notify it immediately of any cybersecurity incident and to provide the information it needs to report to the National CSIRT within the deadlines of Article 9: early warning within three hours, update within 72 hours (24 for an operator of vital importance whose essential services are affected) and final report within 15 calendar days.
  • Security obligations proportionate to the level, consistent with Article 14 quinquies of Law 19.628 once in force and, for bound institutions, with the protocols and standards of the Agencia Nacional de Ciberseguridad (Article 7 of Law 21.663).
  • Audit and inspection rights, with the vendor's duty to produce evidence on request.
  • Termination for breach of any of the above, without compensation, and survival of the duties of confidentiality and return of data.

How it fits with the other reviews

Vendor review is an ongoing compliance process; on the criminal side, the prevention officer leads it. The review of a company being acquired is a one-off exercise, with its own method, covered in legal due diligence. The tiering of vendors feeds the risk map of the prevention model and, in institutions bound by Law 21.663, the risk management of the Cybersecurity Framework Law; contracts with processors become part of the data protection compliance documentation. That way, each vendor has a single file for all three laws.

Frequently asked questions

Does Chilean law require a formal vendor due diligence?

Not under that name. What exists are rules that make the company answer for what certain third parties do, or that require it to manage the risk they bring: Law 20.393, for the crimes of those who manage its affairs before others; Law 19.628, for the mandatario that processes its personal data (today, Article 8; from the entry into force of Law 21.719, Article 15 bis), and Law 21.663, through the duties it imposes on the regulated institution. The review is the reasonable way to comply with those rules. In addition, for the prevention model to exempt the company from liability, Article 4 of Law 20.393 expects it to identify the processes with criminal risk, and procurement is usually among them.

For which vendors can my company be criminally liable?

Two groups, under Article 3 of Law 20.393. The first is the natural person who holds a position, function or post in the company, or who provides it services managing its affairs before third parties, with or without its representation. The second, added by the second paragraph, is the natural person linked to another legal entity that provides it those services or that lacks operational autonomy with respect to it, where there are ownership or participation relations between them. The law does not clarify whether this last requirement applies to both hypotheses or only to the lack of autonomy. Agents, permit managers, debt collectors and group entities that act before third parties on the company's behalf fit that description. Unrelated external companies, such as a customs agency or a collection company, are debatable cases best handled at the highest review level. The same goes for distributors that manage the company's affairs before authorities or clients, with or without its representation. A distributor that buys and resells on its own account normally does not manage the company's affairs.

What must the contract with a data processor contain?

Today Article 8 of Law 19.628 governs: the mandate must be in writing, with the conditions for using the data. Law 21.719 enters into force on December 1, 2026, a date a pending bill proposes to postpone to December 1, 2027. From then on, Article 15 bis will set the minimum: the object of the assignment, its duration, the purpose of the processing, the type of personal data, the categories of data subjects and the rights and obligations of the parties. Subcontracting will require specific written authorization, the processor will be obliged to inform the controller of security breaches and, once the service ends, the data will be deleted or returned. The law instructs the Agencia de Protección de Datos Personales to publish model contracts.

If the processor misuses the data, who is liable?

Once Law 21.719 is in force, the processor will be considered a controller for all legal purposes when it processes the data for a purpose other than the one agreed or transfers them without express authorization: it will answer personally for infringements and jointly and severally with the controller for damages (Article 15 bis). Until then, towards the data subject the controller of the database is liable and must compensate the economic and moral damage caused by the improper processing (Article 23 of Law 19.628). Towards the controller, the mandatario answers under Article 8 and the general rules on mandate. Under both regimes, the contract and the evidence of the instructions given are the first proof the controller has.

Does the Cybersecurity Law impose duties on our vendors?

It depends on the vendor. If it provides digital services or managed information technology services, Law 21.663 treats it as a provider of an essential service (Article 4), a category the law does not define, and imposes its own duties on it: permanent security measures (Article 7) and incident reporting to the National CSIRT (Article 9). The same applies to a vendor that carries out another of the activities Article 4 classifies as an essential service, such as electricity distribution, telecommunications or banking and financial services. The law does not directly bind the other vendors. The regulated institution answers for its general measures (Article 7). If it is an operator of vital importance or the Agency identified its infrastructures or processes as essential (Article 4, final paragraph), it also answers for the information security management system and the continuity plans (Article 8). It reaches its vendors through its risk management and its contracts. For State bodies, Article 9 requires heads of service to demand that information technology vendors share information on vulnerabilities and incidents, and prohibits, with safeguards for confidentiality and intellectual property, clauses that restrict that communication.

How deep should the review of a small vendor be?

The depth depends on the risk of the relationship. A small agent who deals with public officials on the company's behalf sits at the highest level; a large supplier of standard goods with no access to its data or to authorities sits at the lowest. The levels table sets out the criteria, and what has to be documented is why each vendor ended up where it did.

Official sources

Related content

Transform Your Legal Challenges into Competitive Advantages

Discover how our innovative approach can drive your business

© 2026 AnguitaOsorio, all rights reserved.
Chile

Contact

Contáctanos

Phone:

+56 2 2760 4512

Location:

Cerro el Plomo 5420, office 1306, Las Condes, Metropolitan Region.